❌

Reading view

There are new articles available, click to refresh the page.

The Aosu R1 Ultra is a great subscription-free video, albeit with some minor flaws

Aosu Video Doorbell R1 Ultra: two-minute review

Doorbell brands usually sell you the hardware cheap and charge you monthly for the privilege of seeing the footage. Aosu has gone the other way, and for that alone the R1 Ultra is worth your attention.

Video clips go to the AosuBase Mini, a small plug-in box that lives inside your house and does three jobs at once — Wi-Fi bridge, indoor chime, and storage. It holds 8GB and keeps a rolling 60 days of footage.

There is an optional cloud subscription, AosuProtect+, but unlike Ring's arrangement, the doorbell isn't hobbled without it. You get alerts, live view, two-way talk, custom detection zones, and full playback for nothing other than the purchase price.

Aosu Video Doorbell R1 Ultra on stone surface

(Image credit: Future)

Detection is another strength. Rather than relying on a passive infrared sensor and hoping, Aosu layers radar and AI human recognition on top, which lets it judge distance and intent — approaching versus passing, lingering versus walking through.

There's also a Tone button hiding in the two-way talk screen. Tap it, and you can answer the door as either 'uncle' or 'clown', with Aosu's straight-faced explanation that this disguises your voice for privacy.

The uncle setting artificially deepens voices, transitioning women and children to something resembling a man to deter would-be intruders. Clown goes all high-pitched and distorted to mask your identity.

Aosu Video Doorbell R1 Ultra screengrab from app

(Image credit: Future)

Fortunately, the latter falls on the right side of sinister, so you can forget scaring off trick-or-treaters with imitations of South Park’s Mickey Mouse.

Where Aosu gets ahead of itself is resolution and framing. The sensor is 2560 x 1920, which is 4.9 megapixels in a 4:3 frame. That’s sharp, and a step up from 2K doorbells at this price, but not the claimed ‘UHD’, which would be 3,840 x 2,160.

The asserted 60% improvement over standard 2K only holds if the 2K you're comparing against is Aosu's own 3MP doorbell. An earlier version of the identical claim, on the identical camera, said 40%.

Screengrab of footage in Aosu Video Doorbell R1 Ultra app

(Image credit: Future)

Field of view should be taken with a pinch of salt, too. Aosu says 166 degrees, but that's the corner-to-corner measurement. In reality, it's 133 horizontal by 103 vertical, shot in a shallow 4:3 aspect ratio and no head-to-toe image tricks.

With realistic use, the battery should last six months between charges. The kicker is the cell isn’t quick-release, and juicing it from flat to full takes six hours. So that means unclipping the entire doorbell and going without it for quite a while.

Aosu Video Doorbell R1 Ultra: price & availability

  • List price: £139.99 / $135.99 (about AU$190)
  • Launched July 2026 in the UK
  • Available in the UK, US, and across the EU

With a list price of $135.99 / £139.99 (about AU$190), but usually discounted, the R1 Ultra is filed under ‘affordable’ and veers towards bargain territory if you find one hovering around the £100 mark.

At that price, the value case is strong, because the base station is in the box rather than a £50 upsell, and the 60 days of local recording would cost you a subscription almost anywhere else.

Over three years, that's the difference between a hundred pounds and several hundred more.

  • Value score: 4/5

Aosu Video Doorbell R1 Ultra: subscription costs

The R1 Ultra is fully functional without a subscription. Alerts, live view, two-way talk, detection zones, and 60 days of local playback are all included.

AosuProtect+ is the optional cloud add-on. In the UK, it's advertised at £9.99 (about $10 / AU$20) a month or £122.99 (about $160 / AU$230) a year, currently discounted to £3.49 (about $5 / AU$10) and £39.99 (about $50 / AU$80). Treat the higher figures with the same suspicion as the hardware list price.

The annual price is simply the monthly rate multiplied by twelve, so there's no built-in saving for paying up front, and £3.49 lands within pennies of what Aosu charges in dollars in the US. There’s a 30-day free trial if you wish to dip your toe.

Aosu Video Doorbell R1 Ultra subscription details in app

(Image credit: Future)

What it buys you is cloud backup rather than capability: 14 or 30 days of event recordings, playback from anywhere, faster scrubbing, and bulk downloads. AI facial recognition sits on the top tier and is offered for video doorbells only.

The argument for paying is that local storage is bound to the base station like Bilbo Baggins is bound to the ring in The Lord of The Rings. If it fails, someone takes it, or you inexplicably drop it in the fires of Mount Doom, your footage dies with it.

Aosu Video Doorbell R1 Ultra: specs

Feature

Specification

Type

Battery-powered or hardwired video doorbell; base station required

Resolution

5MP (2560 x 1920) with WDR

Zoom

6 x digital

View

4:3 aspect ratio

Field of view

166 degrees diagonal [133 x 103 degrees]

Night vision

Infrared up to 6 feet / 10m

Audio

Two-way talk with voice disguise features

Motion detection

Radar, PIR and AI human recognition; customizable zones

Power

Rechargeable battery 5,000mAh, non-removable; USB-C cable included; 6 hours from flat; hardwire (8–24VAC)

Connectivity

Doorbell 2.4GHz only; AosuBase Mini dual-band 2.4GHz / 5GHz

Smart detection

AI human recognition; facial recognition requires AosuProtect+

Storage

Local, 8GB on AosuBase Mini, 60-day loop, no subscription; optional cloud with AosuProtect+

Smart home

Amazon Alexa, Google Assistant

Tamper protection

Pry detection with chime alert; footage retained locally

Weather

IP65

Finish

Black/silver

Dimensions

5 x 2 x 3 inches / 12.7 x 5.1 x 7.6cm

Aosu Video Doorbell R1 Ultra: design and installation

  • Plain but solid
  • Hub required indoors
  • Battery or existing wiring

The R1 Ultra is a black plastic slab with silver flourishes similar to a Ring, and very little design ambition beyond flattering imitation.

Installation is straightforward and takes about half an hour all in. Bracket on the wall, doorbell clipped on top, base station plugged in somewhere central.

Aosu Video Doorbell R1 Ultra with accessories straight from box

(Image credit: Future)

Aosu recommends mounting at 4 feet / 1.2 meters rather than eye-level, which is lower than instinct suggests but necessary if you want the frame to reach the doorstep. Worth getting right the first time rather than re-drilling.

A 15-degree wedge is included if you need to angle it towards a path or a gate, along with a screwdriver, extension wires and wire nuts for anyone hardwiring to existing 8–24V doorbell wiring.

The base station isn't optional, and it isn't outdoors-rated. It's the storage, the chime, and the Wi-Fi bridge in one. It needs a mains socket permanently, and it's rated only to 14°F / −10°C, so it lives in the hall or the cupboard under the stairs and stays there.

Aosu Video Doorbell R1 Ultra chime plugged in

(Image credit: Future)

Detaching the whole unit from the wall for a full six-hour recharge via USB-C is a weak point, but a cable is bundled in the box.

A neat addition is pry detection. Try to lever the unit off its bracket, and it sounds a chime and pushes an alert, with footage on the base station indoors rather than on what’s being stolen.

  • Design score: 3.5/5

Aosu Video Doorbell R1 Ultra: performance

  • Sharp in daylight
  • Strong multi-sensor detection
  • Infrared-only after dark

Daylight is this doorbell’s happy place, with 5MP more than most similarly-priced rivals offer. Faces, delivery uniforms and parcel labels are legible rather than merely present.

Radar handles distance and movement, PIR picks up body heat, and the AI layer decides whether what it's looking at is a person. During testing, alerts felt instantaneous once someone reached the door.

After dark, expectations need managing. There is no color night vision and no spotlight.

Footage from Aosu Video Doorbell R1 Ultra in app
Future
Aosu Video Doorbell R1 Ultra footage in app
Future
Night time footage from Aosu Video Doorbell R1 Ultra in app
Future

Eight 850nm infrared LEDs offer monochrome up to 33 feet / 10 meters, and the manual warns mounting too close to a side wall will bounce IR back into the lens and fog the image. I’d pair the R1 Ultra with an outdoor light to make up for the shortfall.

Answering the door is well handled. Notifications arrive with a thumbnail of whatever triggered them, so you can tell a courier from a cat without opening the app, and tapping through starts a proper two-way video call rather than a one-way stream.

The 6x digital zoom lets you crop into a face or a label, though at 15fps and with a wide lens, it softens quickly.

Aosu Video Doorbell R1 Ultra footage in app
Future
Footage from Aosu Video Doorbell R1 Ultra in app
Future

Quick Reply issues an audible preset message when you can't talk. Somewhat boringly, they’re fixed, so you can’t edit the wording or add your own.

On connectivity, the doorbell itself is 2.4GHz only; the dual-band capability belongs to the AosuBase Mini, which talks to your router on 2.4 or 5GHz.

That's a sensible design for a battery device, but it means the camera-to-base link is on the crowded band and placement of the base matters more than usual. Plugged in 33 feet / 10 meters from my front door with the broadband router halfway, all was fine.

Live view includes a UHD/SD toggle to drop the quality when the connection struggles, and you can save a clip or a still straight to your phone's camera roll if you ever need to hand something to a neighbor or the police.

The six-month battery figure assumes up to ten events a day at 20 seconds each — about three-and-a-half minutes of recording daily. On a busy porch with a path or pavement in frame, expect considerably less.

  • Performance score: 3/5

Should you buy the Aosu Video Doorbell R1 Ultra?

Attribute

Notes

Score

Value

Local storage, included base station, and no monthly fee at around £100 make the maths hard to argue with.

4/5

Design

Solid and easy to install, but the base station needs a permanent socket, and recharging equals doorbell removal.

3.5/5

Performance

Sharp daylight video and excellent multi-sensor detection, let down by infrared-only night vision and overstated specs.

3/5

Buy it if

You're sick of subscriptions

Sixty days of local recording on the included base, with nothing important behind a paywall, is undoubtedly attractive.

You'd rather not be yourself

Uncle and clown voice settings let anyone home alone answer the door sounding like someone else.

You want fewer useless alerts

The radar, PIR, and AI combination is a real step up from the single-sensor budget crowd, and it shows in your notification tray.

You have existing doorbell wiring

Hardwiring to 8–24V takes the recharging problem off the table entirely, and this is one of the cheaper doorbells that supports it.

Don't buy it if

You need to see faces after dark

Infrared monochrome to 33 feet / 10 meters is all you get. There's no spotlight and no color low-light mode, so a night clip tells you someone was there, but not necessarily who.

You don’t want to remove the doorbell

No quick-release battery means every recharge is a six-hour outage with the unit off the wall and on your kitchen counter.

Aosu Video Doorbell R1 Ultra: also consider

Ring Battery Video Doorbell (2nd Gen)

Cheaper, shoots Retinal 2K with a genuine head-to-toe 1:1 view and color night vision, and installs without a hub. The trade-off is Ring's subscription model and Amazon's data record.

Eufy Video Doorbell C31

The closest like-for-like on the no-monthly-fee promise, with 2K video and a quick-release battery, though you'll want a HomeBase to get the most from it.

How I tested the Aosu Video Doorbell R1 Ultra

  • Fitted to a domestic front door
  • Assessed daylight and infrared video, detection accuracy, and audio
  • Ran entirely without a subscription


I mounted the R1 Ultra on my own front door and used it as the household's main entry camera for a fortnight, deliberately running it on local storage alone so the no-subscription claim could be tested as most buyers will experience it.

I checked live-view responsiveness and alert latency, reviewed clips in daylight and after dark, and tracked battery drain against Aosu's 180-day claim.

First reviewed September 2026

Bitdefender first to launch free 'temporary' VPN for AI Agents because they're worth it — but you can only use it on Apple M-series Macs for now

  • Bitdefender launches privacy tool built specifically for autonomous AI agents
  • Each agent task gets a disposable, temporary connection that deactivates when the task is done
  • VPN for AI Agents runs on a Model Context Protocol server architecture entirely

Bitdefender has introduced VPN for AI Agents, a standalone privacy tool built specifically for the autonomous software agents now browsing, researching, and transacting on behalf of everyday users.

The company says this public beta is a direct answer to the growing anxiety over machine-driven data exposure.

Unlike a conventional privacy tool that stays connected at all times, this tool activates only when an AI agent needs it, then deactivates once the task is done.

Why agents need their own privacy layer

Cybersecurity researchers have increasingly warned that autonomous agents occupy an ambiguous identity space, often borrowing a person's own credentials or shared workload logins to complete tasks online.

Without a clear separation, every website an agent visits and every transaction it completes remains traceable back to a single household IP address.

Recent Pew Research Center data found 71% of adults in the United States believe wider AI adoption will make their personal data less secure, a fear that extends well beyond American borders.

Bitdefender's new offering, built on a Model Context Protocol server architecture, spins up a disposable digital workspace for each prompt and discards it when the task is done.

Each prompt opens its own encrypted tunnel and exits through the VPN server's IP address, so no cookies, cache, or session state carries over to the next task.

The tool covers network transport and IP masking only, leaving the actual content of a prompt exchanged directly between the user and whichever AI provider is running it.

"AI agents are quickly becoming an extension of the people who use them, showing up in both our workdays and our personal lives," said Ciprian Istrate, senior vice president of operations, Consumer Solutions Group at Bitdefender.

"That means security can no longer stop at protecting the person behind the screen; it has to extend to the agent itself acting on their behalf."

This approach treats each agent like an independent team member requiring its own security boundary rather than inheriting the user's existing protections wholesale.

Bitdefender also describes this as clean-IP browsing, useful for QA checks on pages that display different content depending on the visitor's country.

The tool supports up to four simultaneous exit locations, or eight under the recommended testing configuration.

Access remains limited during the beta period

For now, the tool works only on macOS devices, though Bitdefender has confirmed plans to expand to additional operating systems after beta testing.

The beta specifically requires macOS 13 or later and an Apple silicon processor, meaning Intel Macs are not supported.

Bitdefender recommends macOS 15, 16 GB of memory, and roughly 10 GB of free disk space for smoother testing.

Once installed, it operates automatically across several popular AI platforms, including Claude Desktop, Cursor, Codex, and OpenCode, without requiring manual configuration from the user.

Bitdefender lists several practical use cases, including letting an agent compare prices across regions or complete multi-country research in one session.

The company frames these tasks as a productivity gain too, since they would otherwise need manual, country-by-country effort from a person.

Bitdefender is explicit about the tool's limits as well. It does not protect a device's other apps or browser.

It also does not hide prompts from the AI provider running them, and does not override a site's terms of service, rate limits, or an existing IP ban.

"With Bitdefender VPN for AI Agents, we're giving students, workers, and everyday consumers the confidence to let their AI agents work freely, knowing their identity and activity stay protected," Istrate added.

VPN for AI Agents public beta is currently available for free, but whether the free offering continues after the beta testing remains to be seen.

Google logo on a black background next to text reading 'Click to follow TechRadar'

Amnezia VPN boosts stability of all apps with a new update

  • AmneziaVPN rolls out version 5.0.3.0 across all apps
  • It brings new XRay-core, TProxy, and minor user updates
  • It includes upgrades for Self-hosted and Premium users

Anti-censorship Amnezia VPN has released a new app version that improves stability, introduces an updated Xray-core, and brings updates for both self-hosted and Premium users.

The move comes after the VPN provider spent months strengthening its security measures to counter the attacks launched by Russian organisations that specifically targeted the best VPNs operating in the region.

Version 5.0.3.0 is available on all devices (version 5.0.3.1 for Android); users can download it from the Amnezia website, GitHub, and the Android and iOS app stores.

Amnezia VPN — censorship-resistant VPN
Amnezia VPN is an affordable, privacy-focused service that prioritizes essentials like security and censorship unblocking over unnecessary extras. All its apps are open-source, albeit more basic than some competitors. It offers both Free and Premium protection, with the latter billed at $28 for six months and $48 for a year. You have 14 days to decide if you like it or not, risk-free, thanks to its money-back guarantee. View Deal

Amnezia VPN 5.0.3.0: what's new?

Rather than a major update with dramatic new features, the new version emphasises general clean-up, maintenance and connection stability.

For example, the XRay protocol, the core component of the proxy that allows users to bypass censorship, has been updated from version 1.3 to 1.4, in line with the adoption of a newer protocol system in the new version.

Additional support for the TProxy container has also been introduced. The Linux support is useful for routing traffic through the VPN at the transparent proxy level, essentially allowing Linux systems to make the traffic appear as if it originates from the user, thereby making it more difficult to block WireGuard connections.

The update also enables self-hosted users to set up a proxy for Telegram by directly going to the “Self-hosted” section to install it.

⚡️The new app version 5.0.3.0 is here.It is now available for all devices (version 5.0.3.1 for Android). Download it from our website or directly from your app store.In this release, we have improved connection stability, updated Xray-core, and added several important updates…September 22, 2026

For Premium users, the VPN has also improved performance when connecting via the VLESS anti-censorship routing protocol.

Additional fixes addressed Android warning log levels, alongside self-hosted default values, links, and other minor issues that have been corrected.

In terms of user changes, the new release includes a Google Play billing library, which was added as a small feature component to handle In-App Purchases (IAP), and a new country was added to the supported dataset, overall boosting the user experience with minor tweaks.

Leave No Trace logo

(Image credit: Future)

NEW: Leave No Trace — A weekly newsletter on digital privacy and online surveillance.

Leave No Trace investigates the companies and governments putting our digital freedom at risk — and the people fighting back.

📩 Subscribe now to get every edition delivered to your inbox every Friday, launching this September.

Relentlessly updating

Amnezia's efforts to combat censorship had largely focused on previous updates, designed to strengthen its anti-detection capabilities in response to the Russian government's increasingly sophisticated Internet censorship regime.

In June, the open-source VPN said it fixed a bug in its AmneziaWG protocol that had previously left its infrastructure vulnerable to a coordinated cyberattack, allegedly carried out by Russia's media regulator, Roskomnadzor (RKN).

In August, the VPN focused again on security by updating its anti-censorship protocol, AmneziaWG, introducing greater variability in traffic patterns to increase the VPN’s invisibility against new detection methods. During the same month, the provider also strengthened its blocking capabilities with a 'mandatory update' for Premium and Free users.

The move came after a crackdown by the government blocked access to more than 20 widely used privacy services, with the scale of the attack suggesting that Roskomnadzor is continuing to boost new sophisticated ways to filter VPNs.

These governmental repressive measures are making it increasingly difficult for citizens to access the free internet. Additionally, the more repressive these attacks are, the more they seem to influence citizens' perception of VPNs as an everyday tool they need, rather than the opposite.

Indeed, research recently showed that they are developing new forms of collaboration to use VPNs, and view the associated costs as just as essential as those for mobile Internet and routine bills.

This Mac malware is somehow using iCloud calendar invites to try and steal your data

  • Kaspersky uncovers MacSync, a Mac infostealer delivered via iCloud calendar events and fake apps
  • Loader fetches instructions from calendar entries, then deploys malware exfiltrating credentials, wallets, and developer data
  • Newer variants add Objective‑C backdoor spoofing Finder, persistence, and expanded targeting of crypto and IT users

Cybercriminals have found a way to use iCloud calendar events and cloud storage to deliver a powerful infostealer to Mac devices.

The malware is called MacSync, and it’s hiding behind fake crypto wallets, or “cracked” commercial software.

Security researchers Kaspersky, who discovered the ongoing campaign, are urging Mac users to exercise caution when downloading programs, especially from third-party websites, and to be very skeptical of apps prompting for their admin password.

Why calendar?

Getting people to download and run malware on their devices is not as easy as it sounds.

The victims need to be somehow tricked into downloading and running an app, and even when they do so, chances are the malicious program will be sniffed out by whatever antivirus solutions the device has running, before it can do any meaningful damage. Also, crooks don’t want to be forced to repeat the process every time they want to deploy a different variant, or type of malware.

So, they resort to all sorts of techniques and workarounds, from DLL sideloading, to malware loaders.

By separating the initial infection and the actual malware, cybercriminals can reduce detection rate and get more flexibility, but it creates a new problem: defenders can monitor the traffic going in and out of different apps and thus detect when a loader is deploying malware.

The challenge then becomes hiding the traffic, and MacSync does it by using the iCloud calendar.

After being downloaded and executed, the loader will reach out to the calendar - which is a totally benign activity that is unlikely to raise any suspicion - and look for a specific public event, pre-built by the attackers. In its description, it will find the instructions, and the location of, the actual infostealer, and deploy it to ultimately compromise the target device. In this case, the location was also in the iCloud.

The loader itself is being advertised through social media, SEO poisoning, and phishing. Victims are directed either to fraudulent websites or social media channels promoting cracked software, or free versions of advanced solutions. In at least one example, Kaspersky saw the loader being advertised as a cryptocurrency wallet. Victims are shown a typical ClickFix error, and told to fix it by pasting a command in the Terminal.

The command deploys the loader which, in turn, installs MacSync.

A "substantial" overhaul

The infostealer emerged in April 2025, and was initially spun out of AMOS, one of the most popular information-stealing variants for the MacOS. It is based on Swift and has, since then, evolved to offer additional capabilities. According to Kaspersky, it can exfiltrate browser history, cookies, saved credentials, cryptocurrency wallet and app data, Telegram data, Keychain data, as well as system and device information. It can exfiltrate SSH, AWS, Kubernetes, Git, and shell configuration files, as well.

Newer variants come with an Objective-C backdoor spoofing the macOS default file manager, Finder. It establishes persistence, terminates notification processes to prevent alerts, and grants the attackers backdoor access, including running AppleScript received from the C2 server, deploying browser extensions, replacing the legitimate Ledger wallet app, collecting additional system information, and more.

Kaspersky also found an undefined command called “live_browser”, which downloads and runs a component named “sn_relay”, whose point has not yet been established.

The new versions “significantly” differ from older ones, Kaspersky said, stressing that the attackers “substantially” overhauled their approach.

“The nature of the data attackers seek to collect from a victim’s device, as well as the categories of applications the stealer disguises itself as, clearly indicates that this malware family primarily targets developers, crypto enthusiasts, and other users associated in some way with IT and the crypto space,” the researchers stressed. “MacSync’s compromise of software developers’ devices poses particular security risks for both end users and corporate systems, opening up expanded opportunities for attackers to further their intrusion.”

The full list of indicators of compromise (IoC) can be found on this link.

'Decades-old' bugs found affecting Windows, Android, macOS and Linux — but the OS makers don't see it as a big deal

  • Graz University researchers found decades‑old flaws in file‑notification subsystems across Linux, Windows, macOS, and Android
  • Side‑channel attacks can infer keystrokes, visited websites, or even steal credentials via unprivileged access
  • Linux shipped partial mitigations (CVE‑2025‑68788); Microsoft and Apple acknowledged but did not patch, demo expected at ACM CCS 2026

Researchers have found a vulnerability in all major operating systems which could, in certain scenarios, allow threat actors to steal login credentials, or track which websites the target is visiting. OS makers, on the other hand, don’t seem all too phased about it.

The bug is described as a side-channel attack - a type of attack in which threat actors simply observe how the system operates and extract valuable secrets through indirect clues. For example, by monitoring how much power the chip takes at any given moment in time, attackers can observe and extract passwords.

It was discovered by security researchers from Austria’s Graz University of Technology: Sudheendra Raghav Neela, Xufan Zhao, Jeanette Angelika Wultsch, Hannes Weissteiner, Florian Draschbacher, Stefan Gast, and Daniel Gruss.

Notifying the system

This particular side-channel vulnerability was found in the file-notification subsystem running in pretty much every OS in existence today. The subsystem is built to notify applications when files on a system change. Not what has changed, just that a change occurred. The bug is allegedly quite old, too.

"We found decades-old bugs on [these operating systems], all rooted in the file-notification subsystems that every modern OS ships to inform applications when files change," said Sudheendra Raghav Neela, a doctoral student at TU Graz, in an email to The Register.

On Linux, the subsystem is called inotify and it’s been affected since 2005. On Android it’s FileObserver (affected since 2008), and on Windows - ReadDirectoryChangesW - flawed since the year 2000. On MacOS, it’s called FSEvents, vulnerable since 2007.

In the paper, the researchers claim file event information can help attackers conclude what other users on a computer are doing. They can launch an inter-keystroke-timing attack, inferring what users are inputting (both locally and remotely), reveal which websites they visit, and possibly even steal login credentials through UI redress.

The problem stems from the fact that unprivileged users are allowed to access the file notification subsystem. This primarily relates to files that can be read by multiple users, but apparently, there are quite a few files on a system that fall into that category.

No patch

"On Linux, watching a readable directory leaks events on files inside it you cannot even read: watching /dev/input gives a notification on every keystroke, which we turn into a local inter-keystroke timing attack with a 93.1–100% [keystroke accuracy] score across seven users and a remote (SSH) one at 100%,” Neela said.

The percentage range means the attack won’t work in all cases, which is more-or-less standard with side-channel attacks. They are notoriously difficult to pull off, which is also likely why most OS makers barely flinched at the news.

All of them were notified of the findings roughly a year ago, and most of them never bothered to address it. Linux introduced some mitigations, including CVE-2025-68788, which prevents inotify from generating certain “access” and “modify” events for special files. The fix was shipped to multiple kernels and Linux distros, but it addresses only part of the broader attack techniques that the researchers described.

Microsoft and Apple apparently acknowledged the findings, but apart from that - did very little. Microsoft told the researchers the behavior of ReadDirectoryChangesW was "by-design", although the feature is undocumented. They believe the ability to monitor file paths across users is not a vulnerability worthy of a patch. The report does not mention Apple doing anything about it, either.

This Blink video doorbell has dropped to an astonishing AU$27.99 in this early Prime Day deal

Video doorbells used to be fixtures in sci-fi media as futuristic tech, but fast-forward to 2026, almost anyone can install one in their home for not much money or effort, with a lot of the best video doorbells making for an easy home security upgrade.

But if you still find those options a bit pricey, the Blink Video Doorbell System discounted to just AU$27.99 ahead of Amazon’s Prime Big Deal Days sale next week, should certainly make for a no-brainer addition to your home.

This discount matches the Blink Video Doorbell System’s last all-time low price during the last Prime Day sale in July. It’s worth noting, though, that many of the features are locked behind the AU$4.95/m Blink Basic or AU$15/m Blink Plus subscription plans, so those costs should be considered if you want video storage, person detection and more. Amazon is also offering a bundle with two Blink Mini 2K+ cameras for AU$48 or 74% off, perfect for a good starter home security system.View Deal

In our Blink Video Doorbell review, we called it one of the easiest security systems to install, with two different mounting options to suit any household, and setting it up within the Blink mobile app with the included Sync Module Core (which serves as the central system hub) takes just three steps.

Our tester found that it has good image quality at 1440p resolution and 30 frames per second, stable video connection, a wide 150º horizontal field of view and battery life rated for up to two years via three AA lithium batteries.

There’s no included indoor chime, but you can pair this doorbell with a Blink Mini camera that’s sold separately (but you can also buy a bundle with two Blink Mini 2K+ cameras for AU$48) or connect via the Alexa app on your phone to an Amazon Fire Stick or Amazon Echo Show to let you see who’s at your door on your TV or smart display.

As mentioned above, lots of features are locked behind a subscription plan, including video recording, cloud video storage, video sharing, person and vehicle detection, even photo capture. The Blink Basic Plan applies to just one device for AU$4.95 per month or AU$49.95 per year, while Blink Plus lets you add an unlimited number of Blink devices for AU$15 per month or AU$150 per year. For most households, though, the former is a good starting point at a reasonable price, which is made even more enticing by the device’s whopping 72% price drop.

Want to explore your options? Amazon has also discounted more Blink video doorbell models and cameras here.

Cloud and AI bills looking a bit high? Your AI agents may have been let loose and run up huge spending costs

  • One simple prompt could lead to swathes of downstream compute, experts warn
  • Attackers could even exploit your uncontrolled AI to run up costs
  • Greater visibility and circuit breakers are two solutions

Data security company Forcepoint has revealed a major issue with AI agents, but unlike many AI security threats, it doesn't involve stealing data or compromising the model.

Instead, if left to its own devices, Forcepoint says agentic AI could actually consume excessive amounts of compute, tokens, API calls or other resources if sufficient safeguards and limits aren't in place, leading to higher-than-anticipated enterprise cloud bills.

Moreover, the company's research argues that the problem has become more important as AI has become more complex.

Enterprises warned to keep an eye on AI agent compute usage

The result of overwhelmingly complex agentic AI systems is that one single and apparently simply user request could lead to tens or hundreds of downstream operations. Forcepoint labels this as 'unbound consumption'.

Crucially, the analysis found that high compute and token consumption could actually be pretty hard to detect and existing security protocols are unlikely to pick it up, because there doesn't even need to be an attacker for the impacts to take place. All you need is a badly configured automation or a long-running AI session to accidentally lead to runaway costs.

However, Forcepoint worries that attackers can indeed step in to exploit this vulnerability, with malicious users generating huge workloads and consuming massive compute for their own benefit after obtaining an enterprise's credentials, letting them pick up the bill.

Solutions can be as complex as agentic AI itself, but they're now more necessary than ever. Firstly, companies should set budgets at multiple, finer levels, such as API keys, individual users and teams. They should also have greater monitoring powers over where costs are attributed to.

But Forcepoint also calls for agentic circuit breakers to prevent workload and costs from compounding.

"Security teams rarely watch cloud billing dashboards. Finance rarely reviews prompt patterns or agent design," security researcher Jyotika Singh wrote in an urge for enterprises to take the risk more seriously.

Google logo on a black background next to text reading 'Click to follow TechRadar'

We are telling AI chatbots our biggest secrets, but Proton warns our privacy is at huge risk

  • 66% of UK AI users have discussed highly sensitive topics with a chatbot
  • Yet, 64% of respondents are worried that chats will be used to profile them
  • Proton's privacy-first chatbot, Lumo, aims to fix this trust gap

Late at night, when you need to vent about a relationship, ask for career advice, or check a worrying health symptom, who do you turn to? For a rapidly growing number of people, it isn't a friend, family member, or doctor; it's a chatbot.

A new piece of research published today by Proton, the Swiss tech firm behind some of the best VPN services on the market, reveals that a staggering 66% of British AI users have discussed at least one sensitive topic with an artificial intelligence assistant.

However, there is a massive contradiction at the heart of this new digital relationship: we are pouring our hearts out to these chatbots, but we do not actually trust them. According to the survey, 42% of UK users have little or no trust in AI companies to protect their private information, and 11% don't trust them at all.

Despite these glaring privacy reservations, 55% of Brits admit that AI has fundamentally changed their everyday decision-making.

Proton VPN – best for privacy
Based in Switzerland, this privacy-first VPN offers good speeds, advanced anti-censorship features, and a server network that spans 145 countries around the world — including across Africa and Asia, where other providers tend to struggle. While its free VPN plan is handy, it comes with limitations. The good news is that upgrading to a premium subscription will cost you only the equivalent of $2.99 per month.View Deal

The ultimate judgment-free zone

So, why are we sharing our most intimate thoughts with machines we don't trust? The answer is simple: freedom from judgment.

While friends and family remain the preferred choice for most sensitive discussions, AI offers a 24/7 digital confidant that won't react with surprise or embarrassment.

Proton's data shows personal finance is the most commonly discussed sensitive topic (33%), followed closely by work or career problems (32%), mental health struggles (27%), and relationship issues (20%).

66% of people have told an ai chatbot something sensitive.Their finances. Their mental health. Their sex life.At most 1 in 5 trust the companies holding that information.1/6 🧵September 24, 2026

"AI is learning far more about us than a search engine ever could," said Eamonn Maguire, Director of AI Engineering at Proton. "We’re not just asking questions. We’re sharing deeply personal context about our health, finances and relationships. And when technology knows that much about us, privacy can't be an afterthought."

The primary worry isn't just about the AI remembering a single chat, or even the risk of human reviewers reading your logs. Users are increasingly terrified of the bigger picture.

In the UK, 64% of respondents are concerned that their vulnerable conversations are being weaponized to build detailed advertising or marketing profiles. Meanwhile, 52% are worried their secrets are being fed back into the machine to train future AI models.

Leave No Trace logo

(Image credit: Future)

NEW: Leave No Trace — A weekly newsletter on digital privacy and online surveillance.

Leave No Trace investigates the companies and governments putting our digital freedom at risk — and the people fighting back.

📩 Subscribe now to get every edition delivered to your inbox every Friday, launching this September.

How Lumo promises a private alternative

Lumo AI by ProtonVPN

(Image credit: Lumo/Edited with Gemini)

Despite these valid fears, Brits are highly receptive to a more secure way forward. A massive 82% of users said they would be more likely to use an AI chatbot specifically designed around privacy, and 44% would be far more willing to share sensitive information if they were given a cast-iron guarantee that their chats wouldn't be used for AI training.

This is exactly where Proton hopes to fill the gap with Lumo. Built with the same end-to-end encryption ethos as the company's famous email client, Lumo is an open-source, privacy-first ChatGPT alternative.

To help users understand the scale of their digital footprint, Proton recently launched AI Paper Trail, a tool from Lumo that visually demonstrates exactly how much personal information an average AI conversation leaks about a user's inner life.

"People have already decided that AI is useful enough to hear their money worries, doubts and everyday concerns. They are handing AI companies their inner lives and biggest secrets on the assumption that they will protect them when it's actually the opposite. AI's business model depends on learning from them" Maguire added.

Hackers are targeting a critical WordPress flaw, so be on your guard

  • WordPress Core flaw CVE‑2026‑87902 (path traversal, 8.1 severity) enables PHP file inclusion and possible RCE
  • Patch released in v7.1.2 and backported to 4.7+; exploitation began within hours, now widespread
  • Admins must urgently update; interim mitigations include blocking traversal sequences and disabling risky ARP/PHP settings

Hackers are actively exploiting a high severity vulnerability in WordPress that can lead to full website takeover, researchers are saying. A patch is available, and WordPress users are urged to upgrade immediately or risk losing access to their assets.

Discovered by security researcher Robert Ressl, the vulnerability in question is tracked as CVE-2026-87902. It is an 8.1/10 (high severity) unauthenticated path traversal flaw affecting WordPress Core. According to WordPress itself, as well as the National Vulnerability Database, the bug can lead to local PHP file inclusion and, in certain scenarios, remote code execution (RCE).

"An unauthenticated attacker can make get_page_template() page-template resolution include a chosen readable local .php file outside the active theme directories," it was said in the official security advisory.

Achieving RCE

WordPress is the world’s number one website hosting and builder platform, powering more than half of all websites active on the internet right now. However, that doesn’t mean all of them are susceptible to RCE. Only websites ticking these boxes are at risk:

Sites with parent or child themes that have a top-level directory with a name starting with ‘page-’ (for example, ‘page-templates).

Threat actors must target a local .PHP file that exists and is readable by the web server

The web server account must be able to read the included file (for example, pearcmd.php, if PHP’s register_argc_argv setting is active)

WordPress said that both the official PHP image for Docker, and the default cPanel configuration, are affected (users must be running a PHP version before 8.5, though).

The issue was fixed in version 7.1.2, which is now available for download. Fixes were also backported to older versions up to 4.7. Releases before 4.8 are not supported, it was said, and will not be getting a fix.

Attacking vulnerable websites

Wordpress security company Patchstack said the first exploitation attempts started roughly five hours after the patch was released, and these were primarily reconnaissance efforts. In the hours to follow, malicious activity increased tenfold, it was said, as crooks started attempting to deliver malicious payloads to vulnerable websites, as well.

“When this post first went up, every request we had seen was reconnaissance against harmless core files,” Patchstack said. “That is no longer true. Attackers are now including pearcmd.php and using it to write PHP files to disk, and public scanning tooling for this CVE is in circulation.”

At first, Patchstack said the attacks were coming from a handful of IP addresses, and advised website admins to simply block them. However, the attacks have now become rather widespread, meaning blocking individual addresses is no longer a viable strategy. They urge everyone to apply the patch without delay:

“The first evening came from a small cluster of addresses. It is now spread across a few hundred, so blocklisting individual sources is not a strategy. The heaviest talkers at the time of writing:

43.250.53.42

180.251.159.243

195.178.110.247

107.189.14.87

45.61.184.170

92.246.130.76

The file write attempts specifically come from a much smaller subset of those addresses, which is the usual pattern of a few operators acting on results that a much larger scanning population produced.”

Those that cannot update immediately should reject traversal sequences in the pagename parameter, Patchstack added. A real page slug never contains one, they added, meaning it can be blocked without affecting normal traffic. Furthermore, disabling register_argc_argv does not fix the inclusion but it does break the pearcmd chain, which is the difference between an information leak and code execution.

Via BleepingComputer

Massive Chinese hack uses AI agents to steal over 600,000 credit cards and hit hundreds of sites with malware

  • Gambit researchers uncovered ongoing AI‑driven skimming campaign stealing 600,000+ payment records since July 2026
  • Attackers used three autonomous harnesses (Strix, Cairn, Hermes) to compromise dozens of retail sites cheaply
  • Victims include major US firms; campaign shows AI enables faster, persistent, low‑cost cyberattacks at scale

In July 2026, a hacker tasked autonomous AI agents to attack retail organizations around the world, deploy credit card skimmers, and steal payment data.

Since then, the bots launched hundreds of attack projects, compromised dozens of organizations, and stole at least 600,000 payment records - and to make matters worse, the campaign is still live, attacking and breaking into websites as we speak.

All of this was reported by security researchers Gambit, who said they managed to recover the operator’s staging server and through it - reconstruct the ongoing campaign. They also saw the skimmers live on victim websites, and sifted through logs and AI claims found on the attacker’s server. In just five days, between September 10 and 15, the agents made 105 attack waves and compromised 27 organizations “to varying degrees.”

Among the victims are a Fortune 500 hospitality company, a “major” US airline, a large private US industrial supplies distributor, and a US online fashion retailer. One of the AI tools would use a website ranking service to produce a list of potential targets, focusing primarily on those running custom-built software.

A fistful of dollars

But the victims are not the “interesting” part of this story - the attackers are. Gambit believes they are financially motivated Chinese threat actors. They are using three AI “harnesses” (frameworks, essentially), which can run almost the entire attack chain autonomously, striking around 10 companies a day, for a handful of dollars per company.

In four weeks, the attackers spent around $7,000, meaning that their entire cost for the operation so far was no more than $18,000. Breaking it down, it means that the attacker spent around $25 per target.

“Spread over the companies attacked, this is a marginal cost of a few US dollars to a few tens of US dollars for each targeted company,” Gambit’s researchers said. “The operator’s own cost review gives a similar figure, a mean of $25.46 over 101 completed scans, from $3.13 for the cheapest target to $79.31 for the most expensive.”

“Where access was achieved, it usually took less than a day, and in many cases just a few hours. We also detected instructions in the attacker’s playbook that could disrupt the operations of a company as a result of data deletion or cleanup procedures run by the agent - and this has indeed happened in some of the breaches,” Gambit said.

The three harnesses

The three harnesses are called Strix, Cairn, and Hermes.

Gambit describes Hermes as an open source autonomous AI agent with a persistent memory, skills that the agent wrote and edited itself, a searchable archive of past sessions, scheduled jobs, and a web console. On the staging server the researchers analyzed, it loaded a Chinese system persona called “SOUL - Red Team Operator”, which contained 121 skills (78 attack skills).

“Hermes is the operator’s console for orchestrating the activity and for direct hacking activities,” Gambit explained. “It used Anthropic’s opus-4.6 (after newer models refused its requests), with 1,951 prompts typed by the human across 260 sessions - only a few prompts per target. The human prompts are short instructions in Chinese, usually launching an attack, tasking the agent with a general next step, or what to do next after achieving access.”

Strix is an open-source AI pentest tool, while Cairn is an autonomous pentest engine. It receives target domains and an objective, such as to get a shell or admin access, then runs for hours until it achieves the objective, times out, or is stopped. Cairn used DeepSeek v4.1 Flash, it was said.

Gambit’s researchers seem to be rather impressed with the campaign. They described it as very low cost, with a level of patience, persistence, and creativity that most human attackers would be “unlikely to sustain”, managing to achieve “far greater results, far faster.”

They have also called to arms, urging organizations to “adapt to a reality where attacks are significantly faster and more comprehensive.” To do that, they must adopt a resilience-first mentality and deploy a security stack that can match the AI on speed.

Many of the affected organizations were notified, and the skimmers were removed, they said.

FBI claims fake cop scams are costing victims billions —here's what to look out for

  • $1.6 billion has been claimed by scammers impersonating police and government officials
  • The FBI’s Internet Crime Complaint Center (IC3) received almost 61,000 complaints concerning such scams between January 2025 and July 2026
  • Some scams targeted foreign nationals and immigrants, threatening to cancel passports or impose extradition, unless payment is made

Between January 2025 and July 2026, the FBI’s Internet Crime Complaint Center received almost 61,000 complaints concerning scams using police and government official impersonation tactics. As a result, around $1.6 billion is believed to have been scammed and extorted.

Tactics used by scammers included unsolicited phone calls and in some cases video calls, with victims losing an average of $26,000 per scam.

Particularly concerning is the targeting of foreign nationals, international students, and immigrant citizens, often with threats to cancel visas and home country passports. Incredibly, 10% of all losses were traced to a single scam, one that targeted fewer than 3% of the victims.

Foreign national victims

According to the FBI, the fake cop/fake government official scam has various angles, from alleging missed jury duty to threatening arrest due to circumstantial links to an alleged crime.

The demand from the scammers, inevitably, is payment.

Making a commitment to extreme lengths of scamming and extortion, the criminals took things to a new level when it came to targeting victims. International students, visiting foreign nationals, and other immigrant citizens were given special treatment. Not only were they threatened with extradition, there was also the implication of victims losing their home country passport.

To convince the target, scammers built actual studio sets, donned uniforms or suits, and appeared in video calls to the victims, who were convinced they were talking to foreign law enforcement agents or US-based diplomats. Creating the illusion of officialdom to sell the scam, victims paid whatever necessary to stay in their adopted country.

How to spot the scam

It is important to note that not all fraud of this type takes place in the US. These may be online or offline, but the so-called fake cop scam is an international criminal phenomenon. So, how do you avoid it?

We’ll assume you’ve answered a call inadvertently rather than having spam calls blocked (that should be set already).

First, remain calm. These situations are designed to impose stress and heightened anxiety. Scammers rely on these factors to cloud their victim’s judgement and force the narrative they are selling (“you missed jury duty”/“your presence in the country is illegal.”)

Second, it is vital to request credentials. Failure to provide these is the first red flag that the person communicating with you is not what they seem. That’s your cue to end the conversation.

Third, check the credentials. It doesn’t matter how long this takes – a legitimate caller will not mind waiting for you to do the necessary background check, even if it means them calling back.

Finally, and most importantly: neither law enforcement, security services, nor the FBI will demand money. If that is happening, it’s time to end the call.

These popular TP-Link home security cameras could be hacked to spy on you while you sleep, experts warn

  • Cybersecurity company OPSWAT found a login bypass and a crash bug in TP-Link's Tapo C200 cameras
  • TP-Link has extended that to include its C120 offering too
  • Anyone on the same network could get admin access, live video, and recordings without requiring the owner's credentials

Security researchers at OPSWAT have detailed two high-severity flaws in TP-Link's Tapo C200, a pan-and-tilt indoor camera listed on Amazon for $26.99 and sold as a baby monitor and pet camera.

The more serious issue is that someone on the same network can log in as the camera's administrator without the password, accessing the live feed and stored recordings.

At least one other bug, which OPSWAT rates as critical in the same disclosure but does not detail, has not been published.

A localized login that requires no authentication

The TP-Link Tapo C200 camera

(Image credit: TP-Link)

The TP-Link Tapo C200, as we noted in previous coverage of the incident, isn't just another security camera that happens to be vulnerable; it is one of the most popular models on the market, clocking in at over 3,000 sales on Amazon alone.

The Tapo C120, in its current iteration, sells over 5,000 units monthly, even as the advisory notes that its V1 hardware version is currently compromised until users update the firmware on their devices.

Both SKUs have received firmware updates that patch the vulnerabilities (CVE-2026-15315 & CVE-2026-15316), which are assigned 'high' scores of 8.7 and 7.1, respectively. However, according to TP-Link, CVE-2026-15316 does not affect the C120 camera.

However, the former vulnerability is the more pressing of the two and, according to OPSWAT, is particularly problematic for users because of how the C120 and C200 cameras function.

Both run a local management interface over HTTPS and use a challenge-response login designed to prove a client knows the owner's password. Khoi Tran, a graduate fellow at OPSWAT, and his mentor, Thai Do of the company's Unit 515 team, found a second verification path in which, under certain conditions, a value the camera hands out during login can be sent back and accepted as a valid authentication response.

The result is an administrator session after a small number of requests, with no password, no existing session, and no requirements for the new 'owner'. As a result, access includes live video, stored footage, and configuration changes.

OPSWAT's researchers pointed out that a C200 used as a baby monitor would expose "live video, night vision, crying detection and two-way audio."

The second flaw, CVE-2026-15316, affects only the C200 and sits in its Wi-Fi onboarding code. Sending the camera an oversized chunk of encrypted Wi-Fi credential data can crash its HTTPS service or restart the device outright, cutting the owner off from management and monitoring until it recovers.

The attacks are somewhat limited in scope: users aiming to exploit such vulnerabilities would need to be on the same Wi-Fi network, or within a certain trusted ecosystem, to begin with.

For now, users upgrading to TP-Link's newest firmware, issued for both models, rectifies both issues, but there might already be another security patch in the works: OPSWAT also found "a critical vulnerability that could allow an attacker to fully compromise the camera," which could then serve as a foothold inside the network.

It is currently holding off on publishing any details about the vulnerability as it waits for TP-Link to issue a patch that rectifies the situation. Neither OPSWAT nor TP-Link, however, has provided a timeline for when the patch will be available to end users.

Privacy policies on top LLMs take over 20 minutes to read, so perhaps it no wonder people are signing their lives over to ChatGPT and others

  • Privacy policies are famously difficult to read, and in the world of LLMs, they’re impenetrable and long
  • The policy for Meta’s Muse Spark is over 14,000 words long, taking almost an hour to read
  • Cybersecurity firm Bridewell carried out the study, assessing the privacy policies of 20 popular LLMs

When you input data into an AI chatbot, you expect it to interpret and process the words or numbers to save you time. But what is it doing with that data? You can check the privacy policy to find out – assuming, that is, that you have the time to do so.

A new study has found that the average time it takes to read a privacy policy for an LLM is 20 minutes – and some are a much longer read.

With around 75% of people admitting to using an AI chatbot at least once a month, understanding where the questions and data queries are going and how they are used is increasingly important.

Ease of reading

Privacy policies provide that understanding, but are they easy to read? A study by Bridewell’s cyber security experts suggests not, with many having a poor Fleisch Reading Ease Score, meaning that in layman’s terms, these documents are pretty impenetrable.

Bridewell’s study assessed privacy policies from 20 large language models (LLMs), and found that the average length of time to read one is 20 minutes. The average word count is 4,603, but the real challenge is understanding the information.

The Flesch Reading Ease Score is a measure of readability devised by Rudolf Flesch in 1948, and is widely used to score texts. A score over 60 is good, whereas a score below that is not. The average Flesch score for these privacy policies is 40.2, suggesting a degree of jargon-based density that most people will not understand.

How, then, might the general public safely use an LLM chatbot like ChatGPT or Google Gemini while in full knowledge of how the information they input is being used?

Training on inputs

In evaluating the LLMs, Bridewell found that 13 of the 20 use inputs and outputs to train their models. Some LLMs offer the option to opt out of training, but others do not. Even where an opt out is possible, it isn’t always clear how to action it.

“It’s essential for users to fully understand how their data is being processed by LLMs, and businesses need clear internal guidance on what can and can't be shared, and ideally proper enterprise accounts with the right protections in place," noted Chris Linnell, Associate Director of Data Privacy at Bridewell,  "employees may be at risk of sharing highly sensitive or confidential information that may end up being used to train LLMs.”

There isn’t just a personal risk from data input into an AI. Employees need to be aware of how they are using the technology for work.

As a rule of thumb, the more complex the LLM (e.g., Meta's Muse Spark, or Moonshot AI’s Kimi K), the longer the privacy policy takes to read.

US bill threatens to turn your VPN into a piracy blocklist

  • A new US proposed law would force internet providers and VPN services to block "foreign piracy sites" via expedited court orders
  • The legislation would apply to ISPs, DNS resolvers, and any VPN provider with at least 100,000 monthly US subscribers
  • Digital rights groups warn the fast-track legal process risks massive overreach, citing similar policies in Europe

A newly introduced bill in the US House of Representatives is threatening to fundamentally change how virtual private networks operate within the country. If passed, the legislation would force VPN providers to actively block access to piracy websites, turning vital privacy tunnels into heavily filtered exit ramps.

The American Copyright Protection Act (ACPA), formally numbered H.R. 10364, was introduced by Representative Darrell Issa (R-CA) on September 16, 2026. The bill aims to give copyright holders a fast-track judicial process to obtain blocking orders against platforms accused of copyright infringement.

Crucially, the ACPA explicitly names VPN services alongside traditional broadband providers and DNS resolvers as entities that must enforce these blocklists. For users who rely on the best VPN software to ensure unrestricted, unmonitored internet access, this legislation poses a direct threat to the core promise of the technology.

The blocking obligations would apply to any VPN service with at least 100,000 monthly US subscribers. This threshold catches almost all major consumer VPN brands, effectively forcing the industry's biggest players to implement nationwide web filters or risk severe legal consequences.

Laura Tyrylyte, privacy advocate at NordVPN, told TechRadar that there are thousands of VPN solutions available for users worldwide; however, "these blocking measures primarily target reputable, paid VPN providers, leaving free VPN services largely untouched."

"Free VPNs are often harder to regulate, and since users who seek to avoid paying for content are unlikely to pay for a VPN either, these services will continue to operate without any impact," she added.

Leave No Trace logo

(Image credit: Future)

NEW: Leave No Trace — A weekly newsletter on digital privacy and online surveillance.

Leave No Trace investigates the companies and governments putting our digital freedom at risk — and the people fighting back.

📩 Subscribe now to get every edition delivered to your inbox every Friday, launching this September.

Fast-track censorship "at the speed of light"

Under the ACPA, a copyright holder can petition a designated federal judge to declare a website a "foreign piracy site." The evidentiary bar for this is surprisingly low, requiring only a "preponderance of the evidence." Once approved, covered providers are given 14 days to object before the blocking order takes effect, though crackdowns on live sports and other time-sensitive material could be executed even faster.

Rep. Issa has made no secret of his desire for aggressive enforcement. Speaking at a June hearing, he framed his goal bluntly: “Can we do it at the speed of sound? Can we do it at the speed of light?”

Digital rights organizations have heavily criticized the proposal. Meredith Rose of Public Knowledge warned that the bill would force any service provider "to disrupt traffic from targeted websites simply accused of copyright infringement."

Meanwhile, Brandon Butler of Re:Create argued the legislation codifies "a one-sided legal process modeled on European site-blocking laws" and "violates American due process, First Amendment rights, and American ingenuity."

To mitigate the risks of false positives, the bill includes an error provision allowing companies wrongly blocked to claim up to $250,000 in damages, though critics argue this offers little financial comfort to innocent small businesses taken offline.

A growing global threat to unfiltered internet

A mobile phone with a generic VPN screen and a world map of the server network in the background.

(Image credit: Getty Images / NurPhoto)

This isn't the first time US lawmakers have targeted VPNs in 2026. The ACPA arrives on the heels of Utah's SB 73, a controversial state law that attempted to regulate VPN use for age verification before facing an enforcement freeze. The ACPA also joins other pending federal proposals, such as the Block BEARD Act and the Foreign Anti-Digital Piracy Act.

However, the real warning signs come from overseas. As Butler noted, the ACPA heavily mirrors aggressive European anti-piracy campaigns, which have already put VPNs in the crosshairs. In countries like Spain and France, court-ordered VPN blocking is already a reality.

These systems have already shown their potential for collateral damage. An analysis by Re:Create found that in Italy, innocent websites remained blocked for an average of 320 days due to overzealous filters. In Spain, over 500,000 websites were wrongly blocked during LaLiga matches, temporarily restricting access to 5.8% of the popular internet.

If the ACPA advances, a VPN's legal jurisdiction will become more vital than ever. US courts cannot automatically enforce orders against providers incorporated in privacy havens like Panama or the British Virgin Islands. Until then, the battle for the open internet continues on Capitol Hill.

Microsoft takes down AI-boosted phishing tool that hit 12,000 accounts

  • Microsoft, UK police, and partners disrupted EvilTokens PhaaS, arresting two suspects and seizing 200+ domains/sites
  • EvilTokens used AI to scale device‑code phishing, compromising 12,000 inboxes across 10,000 organizations globally
  • Platform ran like a startup with subscriptions, dashboards, and AI‑driven targeting; US victims hit hardest

Two people have been arrested, 50 websites were seized, and 150 domains disabled, in a joint operation against the infamous EvilTokens phishing-as-a-service (PhaaS) kit.

In its report, Microsoft said the UK Metropolitan Police Service’s cybercrime team “arrested two men on suspicion of offenses connected with the alleged operation of EvilTokens.”

The two men, whose identities were not disclosed, are aged 32 and 38, and have been released on bail, subject to conditions while the investigation continues. Their digital services and other items have been confiscated, as well.

Among the partners are Health-ISAC, Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, The Shadowserver Foundation, and TRM Labs. We don’t know if these arrests and takedowns will be enough to completely obliterate EvilTokens, or if the platform will continue to operate. Usually, criminal infrastructure is a lot less resilient to disruptions when arrests are made, compared to when law enforcement simply disables the hardware.

The tech startup of organized crime

EvilTokens has been turning heads for a little while now. The platform was first spotted in February 2026, rising quickly to become one of the most widely used PhaaS solutions out there.

It can be bought through Telegram for $1,500, after which there is a recurring $500 subscription cost. Cybercriminals use it to run large-scale, personalized phishing attacks: they can create spoofed websites, landing pages, and other credential-capture assets; they can create custom-tailored phishing emails, and can even grab session tokens, one-time passwords, and other codes designed to protect accounts against phishing, granting attackers access to people’s inboxes.

But what makes EvilTokens particularly impressive is its use of artificial intelligence. The platform comes with an AI assistant that can sift through the inboxes, suggest which targets are of high value, and even how to approach them. Attackers can conduct Microsoft Graph reconnaissance as well, mapping out organizational structure and permissions, keeping access and moving laterally throughout the target network.

Microsoft said it found evidence of large portions of EvilTokens being vibe coded, “with AI helping its creators build the platform itself.”

The researchers also found the platform drawing on capabilities from multiple AI models. Looking at the platform as a whole, it runs like a well-organized startup, with subscription pricing, customer support, management dashboards, and tools designed to move customers from account access toward financial exploitation.

According to Microsoft, EvilTokens facilitated business email compromise (BEC) campaigns that compromised more than 12,000 inboxes in more than 10,000 organizations worldwide. Victims are mostly in wholesale distribution, construction, and financial services, but those in real estate, higher education, and healthcare are not spared, either.

The victims are primarily located in the United States, with notable numbers found in Canada, the United Kingdom, Australia, India, and France. Microsoft said affected customers were notified, and that the company “helped remediate compromised accounts and shared intelligence to support further defensive and investigative action."

Popularizing device-code phishing

Device-code phishing as an attack technique is not that new. More than a year ago, in February 2025, security researchers Huntress reported on Russian threat actors Storm-2372 deploying the same technique, and while it’s been steadily growing in popularity, it wasn’t until EvilTokens’ appearance that it really exploded.

The same researchers said, in June 2026, that EvilTokens was used to run 1,380% more device-code phishing attacks in 2026, compared to the same period last year.

“We’re seeing a clear maturation of the phishing-as-a-service (PhaaS) market as threat actors increasingly integrate AI workflows into their product offerings,” Huntress said in a report.

“The result is directly observable in our telemetry: a 1,380% increase in device code phishing attacks detected between July–December 2025 and January–April 2026, with over 50% of those incidents linked to two major waves of correlated incidents.”

Millions of Russian fast food fans hit in Burger King Russia hack

  • Burger King Russia’s 2024 breach via Mindbox exposed 3.2 million customer records, now leaked online
  • Data includes emails, names, genders, birth dates, phone numbers, and geolocations (2018–2024)
  • Payment details weren’t compromised; users warned of phishing and identity theft risks

Back in 2024, the Russian arm of Burger King suffered a data breach at the hands of unknown threat actors - now, that data has finally been leaked online.

In October 2024, Burger King told TASS, Russia’s national news agency, that unidentified hackers attacked Mindbox, a domestic marketing automation platform the company had been using.

Through Mindbox, the crooks managed to obtain sensitive company data, including information belonging to the customers.

As a customer data and marketing automation platform, Mindbox helps businesses gather and use customer information for personalized, omnichannel marketing campaigns. Its tools cover email and SMS campaigns, push notifications, loyalty programs, chatbots, and more. According to the company, more than 1,100 businesses use its platform, including L’Oréal, Panasonic, KFC, JBL and United Colors of Benetton.

One victim in a supply-chain attack

At the time, there was no word on the nature of the information that was taken, apart from the fact that payment information was not compromised.

"Among the victims of the attack may also be the data of customers of the Burger King restaurant chain," the company said at the time.

“Burger King confirms that among the personal data, the accuracy of which is being clarified, there is no information about payment details: open information about transactions is not transmitted or stored by third parties.”

The details about the hack were also not disclosed. We don’t know if the platform contained a zero-day, or if a company employee had their login credentials or session tokens exposed. Third-party supply chain attacks such as this one are common and often rather disruptive, affecting numerous companies using the same tools. For Mindbox, however, there have been no reports of additional victims.

In its 2024 results announcement, Mindbox said the attack was its “first serious information security incident”, which was quickly detected and contained “thanks to threat detection tools.”

In the aftermath of the breach, Mindbox said it “found and eliminated points where employees without access rights to sensitive data could indirectly obtain them,” hinting that the attack was, in fact, an identity-based attack rather than a zero-day exploit.

The company also “changed development processes to find such points before they get into the product,” and reformed Mindbox's internal role system to make permissions stricter and more granular. It also limited project access scenarios, introduced a mechanism for confirming access by another employee, and introduced mandatory two-factor authentication, among other things.

Have you been pwned?

Today, more details were released on Have I Been Pwned?, a website that aggregates information stolen in various hacks and helps people learn if their email addresses and other information had been compromised in the past. According to the newest entry, more than three million people have had their data exposed in this incident:

“The breach exposed 3.2M unique email addresses along with names, genders, dates of birth, phone numbers and approximate geolocations, with the data spanning 2018 to August 2024,” Have I Been Pwned? writes. “Burger King Russia acknowledged the incident and advised it did not include payment or passport details.”

The latest findings seem to be somewhat in line with what the media reported at the time. According to The Register, initial reports claimed around 5.6 million lines of data as exposed, which included information about a customer’s favorite dish and previous order dates. While this information was not mentioned in the newest report, if every data line includes one email, one name, or one phone number, it could amount to around 5.6 million.

While the information might be a few years old, things like names and birth dates, and genders rarely change, but are vital in identity theft, social engineering, and similar attacks. Burger King users, especially those in Russia, should be wary of incoming email messages, particularly those claiming to come from the fast food chain.

Mistral denies a fresh security breach, but the code on sale looks a lot like May's leak

  • Seller claims to be offering Mistral AI's full source code and says the company was breached again after May 2026 attack
  • Mistral says an investigation found no evidence of new unauthorized access but has not stated whether the listed code is genuine
  • No customer data has surfaced in analyzed samples, and nobody has shown files created after the May incident

A seller on a cybercrime forum says French giant Mistral AI has been hacked again and is offering what they call the company's full source code for sale.

The September 16 2026 post by an account using the handle "mrwho" consists of a listing titled "Selling mistral.ai Source Code" on an English-language cybercrime forum, according to The CyberSec Guru, pricing the material in Monero only before it attempted to steer potential buyers to Session or Telegram.

Mistral AI's own team has refuted this, stating it has "found no evidence to support this claim."

Not Mistral's first hacking-centric PR problem

Mistral's earlier hacking incident is undisputed - in May 2026, the Mini Shai-Hulud supply chain campaign, attributed to the TeamPCP group, spread from compromised TanStack packages to hundreds of npm and PyPI projects.

Mistral's own security advisory MAI-2026-002 says an automated worm led to compromised versions of its SDKs being published for a few hours on May 11 and 12, and that an affected developer device was involved. Microsoft Threat Intelligence found that a poisoned Mistral AI Python package fetched a second-stage credential stealer that allowed the attack to exploit users.

Mistral went further in statements to reporters than in its advisory. It told BleepingComputer that attackers had compromised a codebase management system and "contaminated some of our SDK packages for a brief period," while insisting that hosted services, managed user data, and research and testing environments were untouched. It also told HackRead that only certain non-core repositories were accessed.

TeamPCP, meanwhile, advertised roughly 450 repositories, about 5GB in total, for $25,000, and threatened to dump them for free if no buyer appeared within a week. One can therefore contend that this could be the same dump being remarketed by a different account, and the seller's profile is already suspect.

The CyberSec Guru noted that the account joined in September 2026 and had four posts and a reputation score of 30, despite displaying a top-tier "GOD User" rank. That profile could fit a scam in the making, but as the outlet pointed out, it could also fit a broker fronting for someone else or a freshly minted alias.

HackRead published 24 sample repository names from TeamPCP's May post. FrenchBreaches, which examined the 339-file tree mrwho shared in September, lists several of the same names. At least four of these appear in both: mistral-inference-private, mistral-inference-internal, mistral-finetune-internal, and mistral-common-internal.

This makes it hard to tell whether the purported 'hack' is just a rehash of an existing dump from Mistral's previous breach or a second successful hacking attempt. There is a straightforward test, however: If the September archives contain commits, files, or credentials dated after May 12, or secrets that were still valid after Mistral's cleanup, the seller's claim of a second breach gains real weight. If everything predates the May incident, this is a resale, which is embarrassing for Mistral but not a new security failure.

Of course, locating the archives or examining them would involve paying the ransom in crypto, as required by what could potentially be a scam in the making- a tremendous leap of faith for an account that was created earlier this month, making this essentially a lottery ticket at best for any security researcher attempting to take a closer look.

More and more workers are feeling stressed at work due to security risks

  • More workers are worried about security issues than they were this time last year
  • Three in four say their recovery tools are too difficult for them to use
  • This report says having strong data storage could help

While many of us typically see security as an IT or a leadership issue, it's actually impacting us more than we'd initially thought. New Object First data found that 91% of workers feel uncomfortably stressed at work because of IT security risks – a seven percentage point increase over last year.

But unfortunately, it's a double-edged sword because it all boils down to AI. Nine in 10 say AI tools have improved their productivity, but seven in 10 say the growth of AI-powered threats is a key driver behind their stress.

Additionally, fewer than one-quarter (24%) believe their organisation is suitably equipped to deal with those threats.

AI-driven security threats are actually impacting you and I

While the risk of cyberattacks (50%) is a leading cause for stress at work, high workloads and understaffing (50%) land in joint-first place. Gaps in backup and recovery effectiveness (41%) and pressure to maintain uptime (44%) are also big headaches for workers, implying pressure isn't coming from direct attacks alone, but workload and operations.

For example, three in four (74%) say that their recovery tools are difficult to use without security expertise, leaving regular knowledge workers at a loss. One in five (19%) even say they feel hopeless and overwhelmed during and after an incident.

Naturally, this stress is impacting productivity, with four in five (78%) remarking that stress negatively affected their job performance. Two in five (39%) even said they'd thought about quitting.

"As critical as technology is to cyber resilience, those responsible for protecting and recovering an organization’s data are just as essential," company CEO David Bennett concluded.

Google logo on a black background next to text reading 'Click to follow TechRadar'

This fake LastPass Authenticator app will just shut off your antivirus and leave you open to attack

  • Attackers spoofed LastPass Authenticator via SEO‑poisoned GitHub pages, delivering malicious ZIP files
  • Malware Rapuncel uses DLL sideloading, kills 145 AV products, and steals passwords, wallets, and tokens
  • Campaign ongoing for months; LastPass vaults unaffected, but users urged to download only from trusted sources

Be careful when downloading the LastPass Authenticator app - there are impostors out there that can disable your antivirus and wreak havoc on your computer.

LastPass recently discovered an elaborate scheme to get people infected with malware - a spoofed website, SEO poisoning, DLL sideloading, and a malware loader delivering never-before-seen payload that can kill endpoint protection and antivirus solutions.

According to the password manager, users searching for "LastPass Authenticator download" or similar keywords will get a GitHub page rather high on the search engine results pages. At a glance, the page looks almost identical to the authentic LastPass offering - however, it redirects users to a separate one, hosted on attacker-controlled infrastructure and delivering a large .ZIP file with multiple files.

Among the files are two worth paying attention to: vsdbg.exe, and vsdbg.dll. The .EXE one is renamed to look like a LastPass installer, but it’s in fact a legitimate Microsoft debugging tool. This tool is used to run the malware - the vsdbg.dll file. This is a method called “dll sideloading” where the legitimate program will look for a DLL file in the same folder it’s located, rather than the wider device library. Since the DLL is delivered together with the executable, it is the first one to be run, despite the fact that it’s malicious.

Rapuncel

LastPass shared the malware with security researchers Delphos for analysis, and they’ve named it Rapuncel. No AV engines have been able to spot it, when it was first analyzed.

Once Rapuncel runs, it does a number of things. First, it gains admin-level access to run as SYSTEM, and then installs a kernel driver. The driver, disguised as an NVIDIA graphics component, comes with a hardcoded list of 145 antivirus and endpoint security products, and if any of them are found on the device, they are instantly terminated.

After killing antivirus solutions, the malware gets to work, stealing saved passwords from more than 25 browsers (Chrome, Edge, and other popular ones included), cryptocurrency wallet files from more than 30 wallet apps, Discord login tokens, Steam session tokens, Telegram session data, Windows credential store, all documents with words like “password”, “seed”, “wallet”, or “recovery” in their name, screenshots of every monitor connected to the device, as well as a detailed profile of the system.

Once all of this is harvested, the information is compressed into a .ZIP archive and uploaded to a server under the attackers’ control. To add insult to injury, the kernel driver was given code to intercept all web traffic, allowing the attackers to inject ads, or modify search results, at a whim.

Rapuncel comes with a persistence mechanism, as well, to make sure it continues operating even if the victim spots it. Spotting it should not be too difficult, though - if no antivirus programs are allowed to run on a computer, something is definitely not working properly.

Active for months

Still, the malware installs itself as a Windows service that starts automatically at boot, and then loops continuously, checking for security products and killing them as soon as they’re activated. “The machine may remain fully under the attacker's control until the kernel driver is physically removed,” the researchers explained. “This process requires booting the computer into Safe Mode or using an external recovery tool, because normal Windows tools cannot safely remove software operating at that level while the system is running.”

LastPass and Delphos believe the campaign has been active for months, and that it will continue to operate despite disruption efforts:

“The LastPass lure was a single recent frame in a campaign that has been running for months and shows every sign of continuing after its current infrastructure is burned,” the researchers said. They stressed that this is “opportunistic brand impersonation” and that LastPass systems and customer vaults have not been compromised or involved in any way.

LastPass said it was one of 40 companies spoofed in this campaign and has urged users to only download apps from reputable, vetted sources.

Meta Muse already has a majorly worrying zero-day security issue

  • Researcher Patrick Wardle finds zero‑day in Meta’s new Muse AI assistant,
  • Dubbed not‑a‑mused, the exploit requires local compromise, voice dictation, and app integrations; attackers can hijack tokens and exfiltrate data
  • Meta has been informed but no patch yet; flaw highlights risks of AI assistants with broad permissions

Meta’s new Artificial Intelligence (AI) assistant Muse reportedly carried a zero-day vulnerability that allowed attackers to gain access to people’s apps, such as WhatsApp or email.

However, it’s not as straightforward as your usual zero-day - to exploit it, simply deploying malware will not suffice. Certain features need to be enabled, and certain integrations established before the bug could be leveraged.

Not-a-mused

A little background, for context: Meta recently released Muse, describing it as an assistant that can “book appointments, fill out forms, and handle customer service.” It says the tool, available exclusively for the Mac ecosystem for now, “proactively takes tasks off your plate” and makes purchases, generates images, and creates documents.

To do that, however, it needs to connect to apps such as email, WhatsApp, calendar, or social media accounts - and this connection is the first prerequisite needed to exploit the flaw.

The second prerequisite is voice dictation. The vulnerability was found in the way Muse handles commands received via voice, meaning the attacker must piggyback onto voice commands in order to escalate privileges and access other apps and their content.

Now for the flaw itself. It was discovered by security researcher Patrick Wardle, founder of nonprofit Objective-See. He named it “not-a-mused” and says it hides in an undocumented setting called endo_voyager_dictation_endpoint. When a user narrates a voice command, that instruction is sent and processed in the cloud, where Meta can log it. This setting allows the user to change which endpoint receives the dictation.

Which brings us to the third prerequisite. The threat actor must have local access to be able to change this setting in the first place. In other words, the device must already be compromised in some way, either via remote monitoring and management tools, or via low-level malware (or with physical access).

For the sake of the report, let’s say that a theoretical user checks all the right boxes - they’re running a compromised machine and are talking to Muse that’s already connected to other productivity apps. Instead of reaching Meta’s endpoints, the voice commands are first sent to attacker-controlled infrastructure, where the AI assistant, together with the instructions, also sends authentication tokens for the tool.

If the attacker reacts fast enough, they can grab the token and access their target’s AI tool. If it’s connected to other apps, such as WhatsApp or calendar, they can simply prompt it to extract whatever sensitive information is found inside.

Not-a-mused is therefore a combination of data exfiltration and privilege escalation.

Ironing out the kinks

“We can manipulate the agent and leverage its privileges to do whatever we want,” Wardle told Ars Technica.

“So instead of us having to write a very comprehensive Mac malware stealer, we can just leverage the AI assistant itself.” Wardle said he has developed several proof-of-concept attacks that do things like writing malicious files to disk and snapping pictures, in many cases with no indication to even an alert user.

Meta has been informed, but is yet to comment, or issue a patch.

AI assistants are all the rage nowadays. They’ve turned elaborate answer machines into tools that can complete assignments, even more complex ones. They can book flights and restaurant tables, make purchases, schedule and reschedule calls and meetings, and more. However, to do that, these tools need extensive permissions - something the security community is warning of.

While they’re not openly speaking against it, they are advising caution. There are many stories of AI agents either going rogue, or simply being tricked by malicious actors. For example, a hidden prompt in a phishing email can trick an AI agent tasked with summarizing the message into exfiltrating all .PDF documents from the victim’s inbox.

In the early days of agentic AI, there were reports of assistants simply deleting people’s inboxes.

Assistants are likely here to stay, but there are still quite a few kinks to iron before they can hit the mainstream.

❌